In NocoDB, versions 0.9 to 0.83.8 are vulnerable to Observable Discrepancy in the password-reset feature. When requesting a password reset for a given email address, the application displays an error message when the email isn't registered within the system. This allows attackers to enumerate the registered users' email addresses.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: Mend

Published: 2022-01-09T00:00:00

Updated: 2022-01-10T15:25:26

Reserved: 2021-12-21T00:00:00


Link: CVE-2022-22120

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-01-10T16:15:10.180

Modified: 2022-01-19T18:30:52.887


Link: CVE-2022-22120

JSON object: View

cve-icon Redhat Information

No data.

CWE